Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

fix(auth): SubjectTokenProviderError drops response and duplicates error message in workload identity providers

Aperta Adatta ai principianti
#4,017 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@mohmedmm ci sta già lavorando.

Dal 2/10/2026.

  • #1 di @mohmedmm — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
86/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python

Direzione di ricerca

Inizia in src/openai/auth/_workload.py e analizza la gestione delle eccezioni in k8s_service_account_token_provider, azure_managed_identity_token_provider e gcp_id_token_provider. Riproduci il problema con la risposta HTTP 500 simulata descritta sopra, quindi verifica che SubjectTokenProviderError conservi la risposta ed eviti i messaggi duplicati e il concatenamento ridondante delle eccezioni.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Confirm this is an issue with the Python library and not an underlying OpenAI API
  • This is an issue with the Python library
Describe the bug

In src/openai/auth/_workload.py, the built-in workload identity subject token providers (azure_managed_identity_token_provider(), gcp_id_token_provider(), and k8s_service_account_token_provider()) catch their own intentionally raised SubjectTokenProviderError exceptions inside generic except Exception as e: blocks.

This leads to two issues:

  1. Lost response property: SubjectTokenProviderError defines a response: httpx2.Response | None attribute. The provider functions explicitly pass response=response when the metadata server returns an error status (response.is_error) or an empty body. However, the outer except Exception as e: intercepts this error (as SubjectTokenProviderError inherits from OpenAIError -> Exception) and instantiates a brand new SubjectTokenProviderError(...) without passing response, setting err.response to None. Callers attempting to inspect err.response for headers, status codes, or error details receive None.
  2. Duplicated error message prefixes: The re-wrapped exception message duplicates the prefix (e.g. "Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500").
  3. Redundant exception nesting: A SubjectTokenProviderError is chained as the __cause__ of an identical SubjectTokenProviderError.
To Reproduce

Steps:

  1. Initialize azure_managed_identity_token_provider() or gcp_id_token_provider() with an http_client mock returning an HTTP 500 (or non-200) error.
  2. Call provider["get_token"]().
  3. Catch SubjectTokenProviderError and inspect err.response and str(err).
Code snippets
import httpx2
from openai.auth._workload import azure_managed_identity_token_provider
from openai._exceptions import SubjectTokenProviderError

mock_client = httpx2.Client(
    transport=httpx2.MockTransport(lambda req: httpx2.Response(500, text="Internal Server Error"))
)
provider = azure_managed_identity_token_provider(http_client=mock_client)

try:
    provider["get_token"]()
except SubjectTokenProviderError as err:
    print(f"err.response is: {err.response}")  # Actual: None | Expected: <Response [500]>
    print(f"Error message: {err}")
    print(f"err.__cause__: {repr(err.__cause__)}")

Actual Output:

err.response is: None
Error message: Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500
err.__cause__: SubjectTokenProviderError('Failed to fetch Azure subject token from IMDS: HTTP 500')

Expected Output:
err.response should retain the <Response [500 Internal Server Error]> object attached when the initial SubjectTokenProviderError was raised, and the error message should not contain duplicated prefixes.

Proposed fix

In src/openai/auth/_workload.py:
In k8s_service_account_token_provider, azure_managed_identity_token_provider, and gcp_id_token_provider, re-raise SubjectTokenProviderError before the generic except Exception block:

        except SubjectTokenProviderError:
            raise
        except Exception as e:
            raise SubjectTokenProviderError(f"...: {e}") from e
OS

All platforms (cross-platform library error handling)

Python version

Python 3.10+

Library version

openai v1.x / latest main

Lingua principale
Python
Stelle
31.8k
Fork
7.3k
Merge medio
1g 3h
PR unite (30g)
131

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di openai/openai-python

Tutte le issue di openai/openai-python

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.